CVE-2022-26138

Published Jul 20, 2022

Last updated 2 years ago

Overview

Description
The Atlassian Questions For Confluence app for Confluence Server and Data Center creates a Confluence user account in the confluence-users group with the username disabledsystemuser and a hardcoded password. A remote, unauthenticated attacker with knowledge of the hardcoded password could exploit this to log into Confluence and access all content accessible to users in the confluence-users group. This user account is created when installing versions 2.7.34, 2.7.35, and 3.0.2 of the app.
Source
security@atlassian.com
NVD status
Analyzed

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Known exploits

Data from CISA

Vulnerability name
Atlassian Questions For Confluence App Hard-coded Credentials Vulnerability
Exploit added on
Jul 29, 2022
Exploit action due
Aug 19, 2022
Required action
Apply updates per vendor instructions.

Weaknesses

nvd@nist.gov
CWE-798
security@atlassian.com
CWE-798

Social media

Hype score
Not currently trending

Configurations